Real-world descriptions of how a group, tool or campaign used a technique.
22 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.002 Steganography |
MalwareLightNeuron | LightNeuron is controlled via commands that are embedded into PDFs and JPGs using steganographic methods. |
| T1005 Data from Local System |
MalwareLightNeuron | LightNeuron can collect files from a local system. |
| T1016 System Network Configuration Discovery |
MalwareLightNeuron | LightNeuron gathers information about network adapters using the Win32 API call |
| T1020 Automated Exfiltration |
MalwareLightNeuron | LightNeuron can be configured to automatically exfiltrate files under a specified directory. |
| T1027.013 Encrypted/Encoded File |
MalwareLightNeuron | LightNeuron encrypts its configuration files with AES-256. |
| T1029 Scheduled Transfer |
MalwareLightNeuron | LightNeuron can be configured to exfiltrate data during nighttime or working hours. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareLightNeuron | LightNeuron has used filenames associated with Exchange and Outlook for binary and configuration files, such as |
| T1041 Exfiltration Over C2 Channel |
MalwareLightNeuron | LightNeuron exfiltrates data over its email C2 channel. |
| T1059.003 Windows Command Shell |
MalwareLightNeuron | LightNeuron is capable of executing commands via cmd.exe. |
| T1070.004 File Deletion |
MalwareLightNeuron | LightNeuron has a function to delete files. |
| T1071.003 Mail Protocols |
MalwareLightNeuron | LightNeuron uses SMTP for C2. |
| T1074.001 Local Data Staging |
MalwareLightNeuron | LightNeuron can store email data in files and directories specified in its configuration, such as |
| T1082 System Information Discovery |
MalwareLightNeuron | LightNeuron gathers the victim computer name using the Win32 API call |
| T1105 Ingress Tool Transfer |
MalwareLightNeuron | LightNeuron has the ability to download and execute additional files. |
| T1106 Native API |
MalwareLightNeuron | LightNeuron is capable of starting a process using CreateProcess. |
| T1114.002 Remote Email Collection |
MalwareLightNeuron | LightNeuron collects Exchange emails matching rules specified in its configuration. |
| T1119 Automated Collection |
MalwareLightNeuron | LightNeuron can be configured to automatically collect files under a specified directory. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLightNeuron | LightNeuron has used AES and XOR to decrypt configuration files and commands. |
| T1505.002 Transport Agent |
MalwareLightNeuron | LightNeuron has used a malicious Microsoft Exchange transport agent for persistence. |
| T1560 Archive Collected Data |
MalwareLightNeuron | LightNeuron contains a function to encrypt and store emails that it collects. |
| T1565.002 Transmitted Data Manipulation |
MalwareLightNeuron | LightNeuron is capable of modifying email content, headers, and attachments during transit. |
| T1573.001 Symmetric Cryptography |
MalwareLightNeuron | LightNeuron uses AES to encrypt C2 traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.